## Overview

### Detection

Phisher
 Score: 48 Range: 0 - 100 Whitelisted: false Confidence: 100%

### Signatures

Yara detected Phisher
Found iframes
HTML body contains low number of good links
HTML title does not match URL

### Classification

 System is w10x64iexplore.exe (PID: 7112 cmdline: 'C:\Program Files\Internet Explorer\iexplore.exe' -Embedding MD5: 6465CB92B25A7BC1DF8E01D8AC5E7596)iexplore.exe (PID: 7156 cmdline: 'C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE' SCODEF:7112 CREDAT:17410 /prefetch:2 MD5: 071277CC2E3DF41EEEA8013E2AB58D5A)cleanup

## Malware Configuration

No configs have been found
SourceRuleDescriptionAuthorStrings
C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\B87Z87FM\ZfpGsvFNKRgtdlqy[1].htmJoeSecurity_Phisher_2Yara detected PhisherJoe Security

## Sigma Overview

No Sigma rule has matched

## Signature Overview

### Phishing:

 Yara detected Phisher Show sources
 Source: Yara match File source: C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\B87Z87FM\ZfpGsvFNKRgtdlqy[1].htm, type: DROPPED
 Found iframes Show sources
 HTML body contains low number of good links Show sources
 Source: http://submit.trmnx-ext.com/unsub/SRsYlDE4kaLvFVl7gzHp2U5E0zN5Umy7DZ3wBzazb7agLHGi40xLzxtQAW9X1sZe HTTP Parser: Number of links: 0 Source: http://submit.trmnx-ext.com/unsub/SRsYlDE4kaLvFVl7gzHp2U5E0zN5Umy7DZ3wBzazb7agLHGi40xLzxtQAW9X1sZe HTTP Parser: Number of links: 0
 HTML title does not match URL Show sources
 Source: http://submit.trmnx-ext.com/unsub/SRsYlDE4kaLvFVl7gzHp2U5E0zN5Umy7DZ3wBzazb7agLHGi40xLzxtQAW9X1sZe HTTP Parser: Title: Terminix - EXT does not match URL Source: http://submit.trmnx-ext.com/unsub/SRsYlDE4kaLvFVl7gzHp2U5E0zN5Umy7DZ3wBzazb7agLHGi40xLzxtQAW9X1sZe HTTP Parser: Title: Terminix - EXT does not match URL
 None HTTPS page querying sensitive user data (password, username or email) Show sources
 Source: http://submit.trmnx-ext.com/unsub/SRsYlDE4kaLvFVl7gzHp2U5E0zN5Umy7DZ3wBzazb7agLHGi40xLzxtQAW9X1sZe HTTP Parser: Has password / email / username input fields Source: http://submit.trmnx-ext.com/unsub/SRsYlDE4kaLvFVl7gzHp2U5E0zN5Umy7DZ3wBzazb7agLHGi40xLzxtQAW9X1sZe HTTP Parser: Has password / email / username input fields
 META author tag missing Show sources
 Source: https://www.terminix.com/customer-support/privacy/ HTTP Parser: No
 META copyright tag missing Show sources
 Source: https://www.terminix.com/customer-support/privacy/ HTTP Parser: No
 Source: global traffic HTTP traffic detected: HTTP/1.1 200 OKContent-Type: text/htmlContent-Length: 57322Connection: keep-aliveDate: Wed, 23 Sep 2020 18:49:44 GMTCache-Control: no-cacheContent-Encoding: gzipLast-Modified: Mon, 30 Dec 2019 19:55:04 GMTETag: "81b527dd72b51d482ab7c8de129f47ad"Server: AmazonS3X-Cache: Miss from cloudfrontVia: 1.1 666ff4ad81b3b60af3d2241160893ee3.cloudfront.net (CloudFront)X-Amz-Cf-Pop: ZRH50-C1X-Amz-Cf-Id: 5_ao72YqzcjG9f79kEKMQf6_kY4AYHpaO1VaTiYnXKBUiS9hK_4j1Q== Source: global traffic HTTP traffic detected: HTTP/1.1 200 OKDate: Wed, 23 Sep 2020 18:49:43 GMTContent-Type: application/javascript; charset=utf-8Content-Length: 14539Connection: keep-aliveAccess-Control-Allow-Origin: *Cache-Control: public, max-age=30672000Content-Encoding: gzipETag: "5eb03cf3-b12d"Last-Modified: Mon, 04 May 2020 16:04:03 GMTTiming-Allow-Origin: *x-via: cfworker/kvcf-request-id: 055de5e31c0000d70d179e6200000001CF-Cache-Status: HITAge: 618565Expires: Mon, 13 Sep 2021 18:49:43 GMTAccept-Ranges: bytesVary: Accept-EncodingServer: cloudflareCF-RAY: 5d76727e9c39d70d-FRAalt-svc: h3-27=":443"; ma=86400, h3-28=":443"; ma=86400, h3-29=":443"; ma=86400
 Source: global traffic HTTP traffic detected: GET /qs=ua-acacaefejchgadhgjejbhacigdhabababadhahcaccaihfachegahhhjcacb HTTP/1.1Accept: text/html, application/xhtml+xml, image/jxr, */*Accept-Language: en-USUser-Agent: Mozilla/5.0 (Windows NT 10.0; WOW64; Trident/7.0; rv:11.0) like GeckoAccept-Encoding: gzip, deflateHost: wowlosefat.comConnection: Keep-Alive Source: global traffic HTTP traffic detected: GET /rm.php?c=dzln6bhddMJFcZIYlcjezA HTTP/1.1Accept: text/html, application/xhtml+xml, image/jxr, */*Accept-Language: en-USUser-Agent: Mozilla/5.0 (Windows NT 10.0; WOW64; Trident/7.0; rv:11.0) like GeckoAccept-Encoding: gzip, deflateConnection: Keep-AliveHost: bluewaterbest.com Source: global traffic HTTP traffic detected: GET /unsub/SRsYlDE4kaLvFVl7gzHp2U5E0zN5Umy7DZ3wBzazb7agLHGi40xLzxtQAW9X1sZe HTTP/1.1Accept: text/html, application/xhtml+xml, image/jxr, */*Accept-Language: en-USUser-Agent: Mozilla/5.0 (Windows NT 10.0; WOW64; Trident/7.0; rv:11.0) like GeckoAccept-Encoding: gzip, deflateConnection: Keep-AliveHost: submit.trmnx-ext.com Source: global traffic HTTP traffic detected: GET /ajax/libs/URI.js/1.18.2/URI.min.js HTTP/1.1Accept: application/javascript, */*;q=0.8Referer: http://submit.trmnx-ext.com/unsub/SRsYlDE4kaLvFVl7gzHp2U5E0zN5Umy7DZ3wBzazb7agLHGi40xLzxtQAW9X1sZeAccept-Language: en-USUser-Agent: Mozilla/5.0 (Windows NT 10.0; WOW64; Trident/7.0; rv:11.0) like GeckoAccept-Encoding: gzip, deflateHost: cdnjs.cloudflare.comConnection: Keep-Alive Source: global traffic HTTP traffic detected: GET /favicon.ico HTTP/1.1Accept: */*Accept-Encoding: gzip, deflateUser-Agent: Mozilla/5.0 (Windows NT 10.0; WOW64; Trident/7.0; rv:11.0) like GeckoHost: submit.trmnx-ext.comConnection: Keep-Alive
 Found strings which match to known social media urls Show sources
 Performs DNS lookups Show sources
 Source: unknown DNS traffic detected: queries for: wowlosefat.com
 Source: global traffic HTTP traffic detected: HTTP/1.1 404 Not FoundContent-Type: text/html; charset=utf-8Content-Length: 346Connection: keep-aliveDate: Wed, 23 Sep 2020 18:49:43 GMTServer: AmazonS3X-Cache: Error from cloudfrontVia: 1.1 666ff4ad81b3b60af3d2241160893ee3.cloudfront.net (CloudFront)X-Amz-Cf-Pop: ZRH50-C1X-Amz-Cf-Id: SEf4evg5CNRwYjZYg5USoZlgm5961Hj9xyAkb4lkEAIeMvRIiIz-Uw==Data Raw: 3c 68 74 6d 6c 3e 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 34 20 4e 6f 74 20 46 6f 75 6e 64 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0a 3c 62 6f 64 79 3e 0a 3c 68 31 3e 34 30 34 20 4e 6f 74 20 46 6f 75 6e 64 3c 2f 68 31 3e 0a 3c 75 6c 3e 0a 3c 6c 69 3e 43 6f 64 65 3a 20 4e 6f 53 75 63 68 4b 65 79 3c 2f 6c 69 3e 0a 3c 6c 69 3e 4d 65 73 73 61 67 65 3a 20 54 68 65 20 73 70 65 63 69 66 69 65 64 20 6b 65 79 20 64 6f 65 73 20 6e 6f 74 20 65 78 69 73 74 2e 3c 2f 6c 69 3e 0a 3c 6c 69 3e 4b 65 79 3a 20 66 61 76 69 63 6f 6e 2e 69 63 6f 3c 2f 6c 69 3e 0a 3c 6c 69 3e 52 65 71 75 65 73 74 49 64 3a 20 43 41 44 44 45 41 39 39 33 46 32 43 33 46 30 34 3c 2f 6c 69 3e 0a 3c 6c 69 3e 48 6f 73 74 49 64 3a 20 64 74 32 39 56 48 2f 55 68 39 54 61 46 67 4c 77 46 51 61 72 59 44 44 48 58 42 39 2f 46 2b 66 2b 44 64 44 43 4c 75 6f 44 2f 4b 51 7a 6d 75 51 6f 6b 6c 54 34 2f 62 4b 51 59 51 76 74 78 54 7a 4e 47 64 64 4f 36 5a 4b 4d 45 47 38 3d 3c 2f 6c 69 3e 0a 3c 2f 75 6c 3e 0a 3c 68 72 2f 3e 0a 3c 2f 62 6f 64 79 3e 0a 3c 2f 68 74 6d 6c 3e 0a Data Ascii: 404 Not Found

• Code: NoSuchKey
• Message: The specified key does not exist.
• Key: favicon.ico
• HostId: dt29VH/Uh9TaFgLwFQarYDDHXB9/F+f+DdDCLuoD/KQzmuQoklT4/bKQYQvtxTzNGddO6ZKMEG8=

 Urls found in memory or binary data Show sources
 Uses HTTPS Show sources
 Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49741
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49740
Source: unknown Network traffic detected: HTTP traffic on port 49789 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49800 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49781 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49769 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49795 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49734
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49733
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49732
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49731
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49730
Source: unknown Network traffic detected: HTTP traffic on port 49732 -> 443 unknown Network traffic detected: HTTP traffic on port 49820 -> 443 Source: unknown Network traffic detected: HTTP traffic on port 49812 -> 443 Source: unknown Network traffic detected: HTTP traffic on port 49784 -> 443 Source: unknown Network traffic detected: HTTP traffic on port 49806 -> 443 Source: unknown Network traffic detected: HTTP traffic on port 49823 -> 443 Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49729 Source: unknown Network traffic detected: HTTP traffic on port 49798 -> 443 Source: unknown Network traffic detected: HTTP traffic on port 49777 -> 443 Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49726 Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49725 Source: unknown Network traffic detected: HTTP traffic on port 49790 -> 443 Source: unknown Network traffic detected: HTTP traffic on port 49731 -> 443 Source: unknown Network traffic detected: HTTP traffic on port 49819 -> 443 Source: unknown Network traffic detected: HTTP traffic on port 49787 -> 443 Source: unknown Network traffic detected: HTTP traffic on port 49729 -> 443 Source: unknown Network traffic detected: HTTP traffic on port 49748 -> 443 Source: unknown Network traffic detected: HTTP traffic on port 49760 -> 443 Source: unknown Network traffic detected: HTTP traffic on port 49805 -> 443 Source: unknown Network traffic detected: HTTP traffic on port 49751 -> 443 Source: unknown Network traffic detected: HTTP traffic on port 49782 -> 443 Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49799 Source: unknown Network traffic detected: HTTP traffic on port 49734 -> 443 Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49798 Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49797 Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49796 Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49795 Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49792 Source: unknown Network traffic detected: HTTP traffic on port 49822 -> 443 Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49791 Source: unknown Network traffic detected: HTTP traffic on port 49726 -> 443 Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49790 Source: unknown Network traffic detected: HTTP traffic on port 49740 -> 443 Source: unknown Network traffic detected: HTTP traffic on port 49765 -> 443 Source: unknown Network traffic detected: HTTP traffic on port 49768 -> 443 Source: unknown Network traffic detected: HTTP traffic on port 49796 -> 443 Source: unknown Network traffic detected: HTTP traffic on port 49808 -> 443 Source: unknown Network traffic detected: HTTP traffic on port 49811 -> 443 Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49823 Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49789 Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49822 Source: unknown Network traffic detected: HTTP traffic on port 49733 -> 443 Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49788 Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49821 Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49787 Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49820 Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49786 Source: unknown Network traffic detected: HTTP traffic on port 49779 -> 443 Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49785 Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49784 Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49783 Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49782 Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49781 Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49780 Source: unknown Network traffic detected: HTTP traffic on port 49785 -> 443 Source: unknown Network traffic detected: HTTP traffic on port 49807 -> 443 Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49819 Source: unknown Network traffic detected: HTTP traffic on port 49799 -> 443 Source: unknown Network traffic detected: HTTP traffic on port 49791 -> 443 Source: unknown Network traffic detected: HTTP traffic on port 49759 -> 443 Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49779 Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49812 Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49778 Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49811 Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49777 Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49770 Source: unknown Network traffic detected: HTTP traffic on port 49788 -> 443 Source: unknown Network traffic detected: HTTP traffic on port 49780 -> 443 Source: unknown Network traffic detected: HTTP traffic on port 49802 -> 443 Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49808 Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49807 Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49806 Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49805 Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49769 Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49802 Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49768 Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49801 Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49800 Source: unknown Network traffic detected: HTTP traffic on port 49758 -> 443 Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49765 Source: unknown Network traffic detected: HTTP traffic on port 49783 -> 443 Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49764 Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49761 Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49760 Source: unknown Network traffic detected: HTTP traffic on port 49821 -> 443 Source: unknown Network traffic detected: HTTP traffic on port 49725 -> 443 Source: unknown Network traffic detected: HTTP traffic on port 49741 -> 443 Source: unknown Network traffic detected: HTTP traffic on port 49764 -> 443 Source: unknown Network traffic detected: HTTP traffic on port 49770 -> 443 Source: unknown Network traffic detected: HTTP traffic on port 49797 -> 443 Source: unknown Network traffic detected: HTTP traffic on port 49801 -> 443 Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49759 Source: unknown Network traffic detected: HTTP traffic on port 49778 -> 443 Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49758 Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49751 Source: unknown Network traffic detected: HTTP traffic on port 49730 -> 443 Source: unknown Network traffic detected: HTTP traffic on port 49786 -> 443 Source: unknown Network traffic detected: HTTP traffic on port 49761 -> 443 Source: unknown Network traffic detected: HTTP traffic on port 49747 -> 443 Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49748 Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49747 Source: unknown Network traffic detected: HTTP traffic on port 49792 -> 443
 Classification label Show sources
 Source: classification engine Classification label: mal48.phis.win@3/119@44/31
 Creates files inside the user directory Show sources
 Creates temporary files Show sources
 Spawns processes Show sources
 Source: unknown Process created: C:\Program Files\internet explorer\iexplore.exe 'C:\Program Files\Internet Explorer\iexplore.exe' -Embedding Source: unknown Process created: C:\Program Files (x86)\Internet Explorer\iexplore.exe 'C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE' SCODEF:7112 CREDAT:17410 /prefetch:2 Source: C:\Program Files\internet explorer\iexplore.exe Process created: C:\Program Files (x86)\Internet Explorer\iexplore.exe 'C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE' SCODEF:7112 CREDAT:17410 /prefetch:2 Jump to behavior
 Found graphical window changes (likely an installer) Show sources
 Source: Window Recorder Window detected: More than 3 window changes detected
 Uses new MSVCR Dlls Show sources
 Source: C:\Program Files (x86)\Internet Explorer\iexplore.exe File opened: C:\Program Files (x86)\Java\jre1.8.0_211\bin\msvcr100.dll Jump to behavior

## Mitre Att&ck Matrix

Initial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionExfiltrationCommand and ControlNetwork EffectsRemote Service EffectsImpact
Drive-by Compromise1Windows Management InstrumentationPath InterceptionProcess Injection1Masquerading1OS Credential DumpingFile and Directory Discovery1Remote ServicesData from Local SystemExfiltration Over Other Network MediumEncrypted Channel2Eavesdrop on Insecure Network CommunicationRemotely Track Device Without AuthorizationModify System Partition
Default AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization ScriptsProcess Injection1LSASS MemoryApplication Window DiscoveryRemote Desktop ProtocolData from Removable MediaExfiltration Over BluetoothNon-Application Layer Protocol4Exploit SS7 to Redirect Phone Calls/SMSRemotely Wipe Data Without AuthorizationDevice Lockout
Domain AccountsAt (Linux)Logon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared DriveAutomated ExfiltrationApplication Layer Protocol5Exploit SS7 to Track Device LocationObtain Device Cloud BackupsDelete Device Data
Local AccountsAt (Windows)Logon Script (Mac)Logon Script (Mac)Binary PaddingNTDSSystem Network Configuration DiscoveryDistributed Component Object ModelInput CaptureScheduled TransferIngress Tool Transfer4SIM Card SwapCarrier Billing Fraud
